A woman in Nagoya books a car by the hour on a Saturday morning. She joined the service back in 2019, and the app asked her to photograph her driver’s license so it could confirm she was allowed to drive. So she did it once, then forgot the photo existed. Last week it left the company. The Times Car data breach reached 6.6 million accounts, and the record attached to her name carried a picture of her license with her home address printed across it.
Confirmation: confirmed by the company. Times Mobility published a first report on September 25, 2026 and a second report with the investigation results on September 28.
What happened in the Times Car data breach
Times Car is a Japanese car rental and car-sharing service run by Times Mobility, part of the Park24 Group. It covers roughly 29,000 stations across all 47 prefectures.
The company detected unauthorized access to the Times Car website at 09:07 on September 25 and blocked it at 07:25 the following morning. BleepingComputer reports that the intrusion had begun earlier in September, which would mean weeks of quiet access before anyone noticed. In its second report three days later, the company confirmed that attackers had in fact taken data.
The figure is approximately 6.6 million accounts. Notably, it covers current members, former members, applications people left incomplete, and users of the corporate business service. In other words, canceling your membership years ago did not take your record out of the set.
Times Mobility also says it has no evidence so far that the stolen data has been published or used. That is worth knowing. However, it is a statement about today rather than a guarantee about next month, so treat it as a starting point.
What the Times Car data breach exposed
The company’s own list of confirmed items is specific, which makes it easier to reason about than most notices.
- Email addresses, names, home addresses, dates of birth and phone numbers. Together these let a stranger answer a “confirm your identity” question, or send a message that quotes real details back at you.
- Driver’s license details and images of identity documents. This is the unusual part, and the next section deals with it on its own.
- Passwords. The company says it held these in a form it describes as impossible to restore, and that alone keeps an attacker from opening an account with them. Its notice gives no technical detail behind that, so the safe reading is that a reused password is still your problem to fix.
- IDs for nine linked services, including WESTER ID. A linked identifier tells an attacker which other accounts to go looking for.
- No credit card data. The company confirmed explicitly that the breach did not include card data.
Why the Times Car data breach’s photographed license is different
You can change a password in a minute. Meanwhile, a driver’s license is harder, and the document image is the thing that makes the difference.
A number on its own is one field in a leak. A photograph, on the other hand, is a usable copy of a government document — the right layout, the right typeface, your face, your signature, your address. Because of that, a stranger can present it to a service that verifies identity by asking for a picture of your ID. That is how a stranger opens a great many accounts.
So the practical consequence of the Times Car data breach is not that someone drives off in a rental car. Instead, it is that someone opens something in your name months from now, and the fraud arrives by post rather than by push alert. For that reason, the useful response is monitoring, not password panic.
What to do after the Times Car data breach
Most of this has nothing to do with us, and that is the point.
- Change the password you used there, and any place you reused it. Because the company cannot prove for you what a thief can read, reuse is the chain to break. A password manager makes unique passwords practical.
- Turn on the strongest sign-in each important account offers. For your bank and your email in particular, prefer a passkey or an app-generated code over a text message.
- Put a note in your calendar for three months out. Identity misuse from a document leak surfaces slowly, so a single check today proves little. Then check your credit file and any national identity-alert service available to you.
- Expect a follow-up message dressed as Times Car, and expect it to sound informed. It will quote your name, your city, maybe your membership date. Detail is the warm-up, not proof. So go to the company’s site yourself rather than tapping a link in the message.
- Treat any request to “re-verify your ID” as hostile for a while. A fresh photo of your license is exactly what a scammer would want next, and a real company will let you reach that page through its own app.
We saw the same follow-on pattern after the KDDI breach, another Japanese consumer brand with tens of millions of customer records. For a fuller walk-through, here is our guide to what happens once your email address turns up in a data breach.
How OptMsg changes this Times Car data breach exposure
Two things, sized honestly rather than oversold.
First, your OptMsg account has no password. So when a site you signed up to suffers a breach, the pair an attacker ends up holding is your address and that site’s password. That pair cannot open your inbox, because there is nothing on the account for it to match. Above all, your email is how most other accounts get reset, so keeping that door shut keeps the rest shut with it. That is the security-first case in a sentence, and you can create an OptMsg address in a couple of minutes. We wrote up the wider argument in the dangers of using passwords to secure your email account.
Second, mail from a sender you have not approved goes to Trash, not your Inbox, and it auto-deletes after 30 days. As a result, the phish dressed as a car-share membership desk lands there. If many other OptMsg users have opted in to a sender, OptMsg flags that message as a Community Recommendation and sends you a push alert, so a genuine notice sitting in Trash still reaches you.
Here is what the argument does not cover, because overstating it would be worse than saying nothing. It does not undo what happened at Times Mobility — that was another company’s systems. Likewise, it does nothing about a compromised device, a live phishing page you type into, or someone holding your unlocked phone. And it cannot retrieve a photograph of your license that has already been copied. Rather, steps three and five above are the work there.
Create Your Account
Your Inbox. Your Rules.
Frequently asked questions
Was I affected by the Times Car data breach if I canceled my membership? Possibly, yes. The company’s second report says the 6.6 million accounts include former members and applications that were left incomplete, so an old record can still be in the set. Times Mobility says it will contact affected customers in stages.
Were passwords exposed in the Times Car data breach? Passwords are on the company’s confirmed list. Times Mobility states they were stored in a form that cannot be restored, and that accounts cannot be misused with them. The notice gives no further technical detail, so changing the password and anywhere you reused it remains the sensible step.
Was credit card information exposed? No. The company confirmed explicitly that card data was not part of the leak.
Why does a leaked driver’s license image matter more than a leaked password? Because you can replace a password in a minute and a government document takes months. A photograph of a license can also be presented to services that verify identity by asking for a picture of an ID, which is how accounts get opened in someone else’s name.
What should I watch for over the next few months? Messages that quote real details about you, requests to re-verify your identity with a fresh photo, and accounts or credit applications you did not make. Check your credit file at intervals rather than once.
Sources
- Times Mobility, second report on the unauthorized access to the Times Car website, September 28, 2026 — https://share.timescar.jp/news/2026/0928/1815.html
- Times Mobility, first report, September 25, 2026 — https://share.timescar.jp/news/2026/0925/1814.html
- BleepingComputer, “Times Car confirms data breach affecting 6.6 million user accounts,” September 28, 2026 — https://www.bleepingcomputer.com/news/security/times-car-confirms-data-breach-affecting-66-million-user-accounts/
Previous in Breach Breakdown: Supabase Data Leak: 16,326 Databases Sat Open on the Web
Next in Breach Breakdown: Pentagon Data Breach: 3 Million Records Sat Unencrypted for Nine Months